Legal
Privacy Policy
Manafold, LLC · Effective July 28, 2026This policy covers the website and products operated by Manafold, LLC. Because Manafold and Calindex handle different kinds of data, product-specific practices are described separately.
1. Who we are
Manafold, LLC (“Manafold,” “we,” “us”) is an independent software company that develops and operates the Manafold and Calindex applications. Contact support@manafold.dev with any privacy request.
Product policy
2. Manafold (Magic: The Gathering app)
Collection & deck data. Manafold writes user data to an encrypted, account-scoped database on the device. Guest collection, deck, inventory, import, and note data stays on that device and does not use user-data sync.
Account information. Account creation is optional. When you link an account, Manafold processes the identifier, email or private-relay address, and provider information needed for Apple, Google, or enabled email authentication.
Cloud backup & sync. Registered Free and Premium accounts transmit collection, inventory, and deck data to Manafold's service for backup and synchronization. Free cloud backup is currently capped at 1,000 physical cards; Guest remains local-only.
Card scanning & image processing. Production scanning is designed to run on-device first. If hosted fallback is configured and used, a selected card image is transmitted for real-time matching; the application code does not intentionally store that image as collection or account content.
Diagnostics & third-party card data. The mobile app currently ships without third-party ads or a general analytics SDK. Limited operational logs may be processed to keep the service reliable. Card names, images, set details, and price estimates use third-party card data, including Scryfall-derived data.
Payments. Paid subscriptions and in-app purchases are not active in the current release path. This policy will be updated before paid functionality is represented as available.
Account & data deletion. Registered users can permanently delete their account, cloud data, and current device replica from within the app. Users can also delete only the encrypted device copy. Guest data can be removed from the device. See the account deletion guide or contact support@manafold.dev.
Product policy
3. Calindex (calendar & events app)
Apple Calendar & Reminders access. Calindex requests full EventKit access to events because it displays, creates, edits, and deletes Apple Calendar content. The agenda reads calendars you leave visible, with all event calendars visible by default. Apple Reminders uses a separate full-access request only when you choose to connect it. New items are written only to a writable calendar or reminder list you select.
Event data & calendar-provider sync. Apple Calendar and Apple Reminders remain the source of truth. Calindex does not operate an account service or cloud event store. Calendar and reminder providers already configured on your device may sync content that Calindex reads or writes through EventKit; that provider's terms and privacy practices apply.
Pasted text & image recognition. Foundation-based parsing and Apple Vision text recognition run on-device; Calindex does not upload pasted text or source images to a Calindex or Manafold server. Text sent through the Share Sheet or Shortcuts is AES-GCM encrypted in the app group while pending, limited to 20 items, and expires after seven days. When you confirm an event, its details and an import note derived from the original line are written to the calendar you selected and may then sync through that calendar's provider.
Optional import history. On the first text import, Calindex asks whether to keep history. If enabled, raw source text and import records are stored in an AES-GCM encrypted file in the app's local Application Support directory, with a separate device-only Keychain key. History remains until you delete records older than 30 or 90 days, delete all history, securely erase history and pending imports, or remove the app. Deleting history does not delete Apple Calendar events.
Notifications. Optional daily summaries, tomorrow previews, import review and change alerts, and per-event reminders are scheduled locally through iOS. Calindex does not use remote push notifications.
Diagnostics, analytics & SDKs. The current app code has no advertising, tracking, analytics, or diagnostic-upload SDK and no third-party package dependency. It uses Apple system frameworks, and its privacy manifest declares no collected data and no tracking. Operating-system diagnostics, if enabled on your device, are handled by Apple under your device settings.
Accounts & deletion. Calindex has no user accounts and no Calindex cloud backup or sync copy. Settings can securely erase encrypted import history, pending imports, and their keys without changing Apple Calendar or Reminders. Removing the app removes Calindex's local data, while source calendar and reminder content remains. If you explicitly delete a writable event or reminder through Calindex, that deletion applies to the underlying Apple source and may sync through its configured provider.
4. Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal information, and to object to or restrict certain processing. Contact support@manafold.dev to exercise a right.
5. Changes & contact
We may update this policy as our products evolve; material changes will be reflected here with a new effective date. Questions can be sent to support@manafold.dev.